Skip to main content

Positive Technologies (dbugs)

ProductPositive Technologies vulnerability database (dbugs)
Records still shown as active9, every withdrawn identifier against Open WebUI
First contacted2026-08-08
Channels trieddbugs@
StatusAwaiting response

Records

Every CVE withdrawn against Open WebUI still has a live dbugs entry, each with its own PT- identifier, a severity, a description of the defect and a recommendations section. Each identifier below is in the REJECTED state at cve.org and at NVD:

IdentifierWithdrawn byRejected sinceOur assessment
CVE-2024-7033huntr / Protect AI2026-07-16Disposition
CVE-2024-7034huntr / Protect AI2026-07-16Disposition
CVE-2024-7038huntr / Protect AI2026-07-16Disposition
CVE-2024-7039huntr / Protect AI2026-07-16Disposition
CVE-2024-7040huntr / Protect AI2026-07-16Disposition
CVE-2024-7959huntr / Protect AI2026-07-16Disposition
CVE-2025-15603VulDB2026-06-18Disposition
CVE-2025-29446MITRE2026-06-29Disposition
CVE-2025-63391MITRE2026-06-29Disposition

Two entries we can cite directly: PT-2026-24109 for CVE-2025-15603, and PT-2025-17455 for CVE-2025-29446.

The entries tell operators what to do about it

dbugs entries carry a Recommendations section. The advice is specific, actionable and attached to identifiers that no longer exist.

CVE-2025-29446 (PT-2025-17455, CVSS 3.1 rated 3.3 Low, last updated 2025-05-28) advises restricting access to the verify_connection() function in routers/ollama.py "until a patch is available", and suggests that disabling that function "may help minimize the risk of exploitation".

The identifier was withdrawn on 2026-06-29, so no patch is coming. An operator who follows that guidance disables working functionality and waits indefinitely, in response to a defect the issuing CNA has determined was never there.

CVE-2025-15603 (PT-2026-24109) similarly recommends upgrading to a version of Open WebUI later than 0.6.16 in order to remediate. That identifier was withdrawn on 2026-06-18.

Remediation guidance raises the cost of a stale record considerably. A wrong severity misinforms a reader. A wrong recommendation changes what they run.

The record travels further than the database

The dbugs entry for CVE-2025-29446 lists nine references. Alongside NVD and OSV, they include four Telegram channel posts and two Twitter posts announcing the CVE and one reference already marked Deleted.

Those are broadcast channels. A post announcing a CVE is not revised when the identifier is withdrawn, and each one is a copy that outlives the record it came from. A rejection at cve.org reaches none of them.


Contact log

DateChannelOutcome
2026-08-08dbugs@Awaiting response

See also

This content is for informational purposes only and does not constitute a warranty, guarantee, or contractual commitment. Open WebUI is provided "as is." See your license for applicable terms.